This is such a cool project that I hope it goes further, since verifying dependency distribution for correctness on top of all of Rust's other guarantees makes the ecosystem that much easier to justify investing in.
This is such a cool project that I hope it goes further, since verifying dependency distribution for correctness on top of all of Rust's other guarantees makes the ecosystem that much easier to justify investing in.
The Rust ecosystem is pretty good about crate authors not knowingly violating semver. This tool is mostly to keep crate authors from unknowingly violating semver. It's possible that the reason that you haven't noticed is because even if a crate accidentally violates semver by making an unanticipated breaking change to a given API, either you're not using that particular API (who uses 100% of any given library?) or else that the breakage doesn't affect your specific usage (e.g. maybe some type no longer implements a trait, but you weren't using that trait to begin with).
The goal of this tool is to aid in preventing regrettable accidents like that, by informing maintainers about semver issues before they are published.
I've written several blog posts about how semver in Rust is particularly tricky and has unexpected edge cases, if you'd like to see specific examples of things non-obviously going wrong:
Also, I've been working with the cargo team and the plan is to merge cargo-semver-checks into cargo itself, so it runs automatically on `cargo publish`. This would be similar to how cargo checks for uncommitted git changes: it will alert if it finds anything but you can override it if you think that's warranted.